In: Computer Science
According to Figure 4-1 on page 157 of the "Principals of Information Security", all employees have an obligation to report security breaches and vulnerabilities. How does an organization implement this philosophy without creating an environment filled with mistrust and low morale?
Yes, all employees have an obligation to report security breaches and vulnerabilities, and reporting the breaches and vulnerabilities is very essential for the organization as it helps the organization to fix the issues and work efficiently without any reputation and data loss.
To implement this concept/philosophy the organization can make some guidelines for the employees to report the breaches and vulnerabilities, the organization can develop a dedicated portal or platform for the internal employees to report the issues easily and verify the issue and rate the issue to be genuine, this way the mistrust can be overcome, as each employee will have a score on the portal which can tell how correct the reported issues have been till now by a particular employee.
Now, to overcome the possibility of Low Morale the organization can offer some kind of perks or additional bonus to the employees reporting the breaches and vulnerabilities, this way the Morale of the employees will be high and all the employees will enthusiastically report the issue and make the organization grow in a better way.